Apple macOS and Safari Passwords Extension Authentication Bypass Vulnerability

Vulnerability

A vulnerability exists in macOS Sequoia and Safari that allows a malicious application to bypass authentication for browser extensions. This issue arises from inadequate data redaction in system logging, which could potentially be exploited to manipulate or deceive extension authentication processes.

Impact

Exploitation of this vulnerability could lead to unauthorized bypassing of authentication mechanisms for browser extensions, allowing malicious apps to interact with extensions inappropriately or gain elevated privileges through such interactions.

Remediation

Users can update to macOS Sequoia 15.3 or Safari 18.3 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
5.0
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.